Skip to content

CVE-2026-76480 CVE-2026-76482 CVE-2026-76483 CVE-2026-76484

Cisco License On-Prem security hardening release fixes four vulnerabilities (cisco-sa-hardening-ssm-Ph77wdhf)

Critical 10.0 Vendor: Cisco Published

Cisco's October 2026 security hardening release for Cisco License On-Prem (formerly Smart Software Manager On-Prem) fixes four vulnerabilities: CVE-2026-76480, CVE-2026-76482, CVE-2026-76483 and CVE-2026-76484. Three are critical. No workarounds; apply the update.

What happened

Cisco's October 2026 security hardening release for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem, addresses four internally discovered flaws. CVE-2026-76480 is an improper authentication issue with a CVSS score of 9.8. CVE-2026-76482 is an improper input verification issue with a CVSS score of 10. CVE-2026-76483 is insufficiently protected credentials with a CVSS score of 9.1. CVE-2026-76484 is a code injection issue with a CVSS score of 8.8. Cisco rates the first three critical and the fourth high.

All four are reachable over a network. Three of the flaws require no privileges and no user interaction: the improper authentication issue, the input verification issue and the credential protection issue. CVE-2026-76480 and CVE-2026-76482 indicate high impact to confidentiality, integrity and availability. CVE-2026-76482 also has changed scope, so the effect can extend beyond the vulnerable component. CVE-2026-76483 indicates high impact to confidentiality and integrity but no availability impact. CVE-2026-76484 requires a low-privileged account and then indicates high impact to confidentiality, integrity and availability.

Cisco PSIRT states it is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory. Cisco has published software hardening releases to address them, and states there are no workarounds.

Who is affected

Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem. The affected versions listed in Cisco's advisory are 1.1, 1.2, 1.3, 6.3.0, 7-202001, 8-202004, 8-202006 and 8-202012. This is the on-premises license management component used to manage Cisco software licenses. If your deployment is on one of these versions, treat it as affected and plan the update.

What to do now

  1. Apply Cisco's security hardening release for your affected version. The CVE records do not name specific fixed build numbers, so use Cisco's advisory for this bundle to identify the correct release for your deployment.
  2. Do not rely on a configuration change instead of the update. Cisco states there are no workarounds that address these vulnerabilities.
  3. If the update must be scheduled, restrict network access to the Cisco License On-Prem interface so that only trusted administrative networks can reach it, and monitor it for unexplained access.
  4. Review the system for signs of unauthorised access, particularly if it was reachable from untrusted networks before the update.

How to detect it

Cisco has not published indicators of compromise for these flaws. Focus on the management interface: confirm it is not reachable from the internet or other untrusted networks, and review authentication and account-change logs for unexpected remote activity. This is especially relevant for CVE-2026-76480 and CVE-2026-76482, which require no credentials over the network.

Beyond the patch

Beyond this update, these flaws are a reminder that management planes need the same exposure discipline as user-facing systems. Implementation & Assessment Services can test that the hardening release is deployed and that authentication, input validation and code-injection weaknesses are not present elsewhere in the environment. Virtual CISO Services can run exposure management so that unauthenticated paths to internal systems such as licence servers are found before an attacker does. If Cisco is a supplier in your NIS2 or DORA scope, Supply Chain Defense & Third-Party Risk can track Cisco's patch cycle and your exposure window.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484
Cisco License On-Prem
7-202001
1.1
6.3.0
8-202004
8-202006
1.2
1.3
8-202012
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.